Remote Code Execution in Liferay Portal and Liferay DXP Products
CVE-2025-3586
7.5HIGH
What is CVE-2025-3586?
In specific versions of Liferay Portal and Liferay DXP, the Objects module fails to restrict Groovy scripts for Admin Users, enabling remote authenticated administrators to execute arbitrary code. This vulnerability poses significant security risks as it allows for unauthorized execution of scripts, potentially compromising the integrity of the affected systems. In contrast, Liferay DXP configurations do not permit Groovy in Object actions, highlighting the importance of version management and security settings.
Affected Version(s)
DXP 7.4.13-u27 <= 7.4.13-u42
DXP 2023.Q3.1 <= 2023.Q3.10
DXP 2023.Q4.0 <= 2023.Q4.10